—Go
GO-2026-5670· CVE-2026-28736, GHSA-vph7-r229-qxpfFocalboard doesn't validate file ownership when serving uploaded files in github.com/mattermost/focalboard
Modified: 6/25/2026
package
pkg:go/github.com/mattermost/focalboard
Focalboard doesn't validate file ownership when serving uploaded files in github.com/mattermost/focalboard
Modified: 6/25/2026
Focalboard doesn't sanitize category IDs before incorporating them into dynamic SQL statements
Modified: 6/25/2026
Focalboard doesn't validate file ownership when serving uploaded files
Modified: 6/25/2026
Focalboard doesn't sanitize category IDs before incorporating them into dynamic SQL statements in github.com/mattermost/focalboard
Modified: 6/25/2026